CVE-2022-40700
Published: Jan 19, 2024
Modified: Apr 28, 2026
CVSS v3.1
8.2
Description
Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWallet – A virtual wallet for WooCommerce, Long Watch Studio WooVIP – Membership plugin for WordPress and WooCommerce, Long Watch Studio WooSupply – Suppliers, Supply Orders and Stock Management, Squidesma Theme Minifier, Paul Clark Styles styles, Designmodo Inc. WordPress Page Builder – Qards, Philip M. Hofer (Frumph) PHPFreeChat, Arun Basil Lal Custom Login Admin Front-end CSS, Team Agence-Press CSS Adder By Agence-Press, Unihost Confirm Data, deano1987 AMP Toolbox amp-toolbox, Arun Basil Lal Admin CSS MU.This issue affects Montonio for WooCommerce: from n/a through 6.0.1; Wpopal Core Features: from n/a through 1.5.8; ArcStone: from n/a through 4.6.6; WooVirtualWallet – A virtual wallet for WooCommerce: from n/a through 2.2.1; WooVIP – Membership plugin for WordPress and WooCommerce: from n/a through 1.4.4; WooSupply – Suppliers, Supply Orders and Stock Management: from n/a through 1.2.2; Theme Minifier: from n/a through 2.0; Styles: from n/a through 1.2.3; WordPress Page Builder – Qards: from n/a through 1.0.5; PHPFreeChat: from n/a through 0.2.8; Custom Login Admin Front-end CSS: from n/a through 1.4.1; CSS Adder By Agence-Press: from n/a through 1.5.0; Confirm Data: from n/a through 1.0.7; AMP Toolbox: from n/a through 2.1.1; Admin CSS MU: from n/a through 2.6.
| Vendor | Product | Versions |
|---|---|---|
Montonio | Montonio for WooCommerce | affected n/a - <= 6.0.1 |
Wpopal | Wpopal Core Features | affected n/a - <= 1.5.8 |
AMO for WP – Membership Management | ArcStone | affected n/a - <= 4.6.6 |
Long Watch Studio | WooVirtualWallet – A virtual wallet for WooCommerce | affected n/a - <= 2.2.1 |
Long Watch Studio | WooVIP – Membership plugin for WordPress and WooCommerce | affected n/a - <= 1.4.4 |
Long Watch Studio | WooSupply – Suppliers, Supply Orders and Stock Management | affected n/a - <= 1.2.2 |
Squidesma | Theme Minifier | affected n/a - <= 2.0 |
Paul Clark | Styles | affected n/a - <= 1.2.3 |
Designmodo Inc. | WordPress Page Builder – Qards | affected n/a - <= 1.0.5 |
Philip M. Hofer (Frumph) | PHPFreeChat | affected n/a - <= 0.2.8 |
Arun Basil Lal | Custom Login Admin Front-end CSS | affected n/a - <= 1.4.1 |
Team Agence-Press | CSS Adder By Agence-Press | affected n/a - <= 1.5.0 |
Unihost | Confirm Data | affected n/a - <= 1.0.7 |
deano1987 | AMP Toolbox | affected n/a - <= 2.1.1 |
Arun Basil Lal | Admin CSS MU | affected n/a - <= 2.6 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now